Computer system security model based on system call related to security
Jimin Li, Zhen Li, Kunlun Li
Abstract
Jimin Li, Zhen Li, Kunlun Li
Abstract
A computer system security model based on system call related to security is proposed. It is inspired from the biological immune system and overcomes some drawbacks of traditional computer immune system based on system call. It makes the number of system calls intercepted decrease significantly, records the arguments of system call which are useful information for intrusion detection without low efficiency, and distinguishes non-self from self by Sandbox as well as rule matching. Furthermore, our model resolves the unreliability and insecurity of process and the display of process behavior incompletely caused by denying the execution of a system call in traditional Sandbox systems. Experimental results show that different non-self class can be distinguished accurately and non-self can be detected in Sandbox which is unknown type by rule matching without imposing heavy performance impact upon operating system.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A computer system security model based on system call related to security is proposed. It is inspired from the biological immune system and overcomes some drawbacks of traditional computer immune system based on system call. It makes the number of system calls intercepted decrease significantly, records the arguments of system call which are useful information for intrusion detection without low efficiency, and distinguishes non-self from self by Sandbox as well as rule matching. Furthermore, our model resolves the unreliability and insecurity of process and the display of process behavior incompletely caused by denying the execution of a system call in traditional Sandbox systems. Experimental results show that different non-self class can be distinguished accurately and non-self can be detected in Sandbox which is unknown type by rule matching without imposing heavy performance impact upon operating system.
Key concepts: Sandbox (software development), System call, Computer science, Intrusion detection system, Process (computing), Computer security, Matching (statistics), Computer security model